Patentable/Patents/US-8522311
US-8522311

Authentication techniques

PublishedAugust 27, 2013
Assigneenot available in USPTO data we have
Inventorsnot available in USPTO data we have
Technical Abstract

Techniques for authenticating clients of differing capabilities in an efficient manner. Two or more authentication techniques, including one preferred authentication technique, are initiated to run in parallel to authenticate a client. Upon determining that the client can support the preferred authentication technique, the preferred technique is used to authenticate the client and the other authentication techniques are aborted. If it is determined that the client cannot support the preferred authentication technique, then one of the other authentication techniques is used to authenticate the client. In this manner, based upon the capabilities of the client, an appropriate authentication technique is used to authenticate the client in an efficient manner.

Patent Claims
18 claims

Legal claims defining the scope of protection. Each claim is shown in both the original legal language and a plain English translation.

Claim 1

Original Legal Text

1. A method comprising: sending, by a network device to a client to be authenticated, a first message corresponding to a preferred authentication technique; sending, by the network device to an authentication server, a second message corresponding to a non-preferred authentication technique such that processing by the client in response to the first message is performed in parallel to processing by the authentication server in response to the second message; determining, by the network device, whether a response from the client to the first message is received by the network device within a predetermined time period; upon determining that a response from the client to the first message is received by the network device within the predetermined time period, causing the client to be authenticated using the preferred authentication technique instead of the non-preferred authentication technique; and upon determining that a response from the client to the first message is not received by the network device within the predetermined time period, causing the client to be authenticated using the non-preferred authentication technique instead of the preferred authentication technique.

Plain English Translation

A network device authenticates clients by initiating two authentication methods in parallel: a preferred method and a non-preferred method. The device sends a first message related to the preferred method to the client and a second message related to the non-preferred method to an authentication server. If the client responds to the first message within a set time, the device authenticates the client using the preferred method and ignores the non-preferred method. If no response is received from the client within that time, the device uses the non-preferred method for authentication.

Claim 2

Original Legal Text

2. The method of claim 1 wherein the preferred authentication technique is based upon IEEE 802.1x.

Plain English Translation

The client authentication method described above uses IEEE 802.1x as the preferred authentication technique. The network device initiates both an 802.1x authentication and a fallback authentication method simultaneously. Client authentication proceeds using 802.1x if the client supports it; otherwise, the fallback method is used. This allows for faster authentication for 802.1x-compatible clients.

Claim 3

Original Legal Text

3. The method of claim 1 wherein the non-preferred authentication technique uses a medium access control (MAC) address of the client or an Internet Protocol (IP) address of the client.

Plain English Translation

In the client authentication method, the non-preferred fallback authentication method relies on either the client's MAC address or IP address to authenticate. If the preferred method (e.g., 802.1x) fails or times out, the network device uses the client's MAC or IP address to authenticate the client against an authentication server. This provides a basic authentication mechanism for devices that don't support the preferred protocol.

Claim 4

Original Legal Text

4. The method of claim 1 wherein sending the first message comprises sending an Extensible Authentication Protocol (EAP) identifier request to the client.

Plain English Translation

This invention relates to network authentication systems, specifically improving the efficiency and security of authentication protocols between clients and servers. The problem addressed is the need for a more streamlined and secure way to initiate and manage authentication sessions, particularly in environments where multiple authentication methods may be supported. The method involves sending an initial message from a server to a client to begin an authentication process. This message is designed to identify the authentication protocol or method that the server supports, allowing the client to respond appropriately. In one specific implementation, the initial message is an Extensible Authentication Protocol (EAP) identifier request, which prompts the client to provide its identity or authentication credentials. This request helps establish a secure communication channel and ensures that the client and server can proceed with a compatible authentication method. The method may also include additional steps such as receiving a response from the client, validating the response, and completing the authentication process based on the exchanged information. The use of EAP, a widely adopted framework for wireless and wired network authentication, ensures compatibility with various authentication mechanisms, including password-based, certificate-based, and biometric authentication. This approach enhances security by reducing the risk of unauthorized access and improves efficiency by standardizing the authentication initiation process.

Claim 5

Original Legal Text

5. The method of claim 1 wherein sending the second message comprises sending an authentication request based upon a medium access control (MAC) address of the client to the authentication server.

Plain English Translation

As part of the parallel authentication process, the network device sends a second message to an authentication server. This message is an authentication request based on the client's MAC address. The authentication server then uses the MAC address for authentication while the device simultaneously waits for a response from the client to the preferred authentication method.

Claim 6

Original Legal Text

6. The method of claim 1 wherein, upon determining that a response from the client to the first message is received by the network device within the predetermined time period, aborting the non-preferred authentication technique-related processing performed in response to the second message.

Plain English Translation

If the client responds to the preferred authentication method (first message) within a predetermined time, the network device aborts the non-preferred authentication process that was initiated with the second message to the authentication server. This ensures that resources are not wasted on the non-preferred method when the client supports the preferred method.

Claim 7

Original Legal Text

7. The method of claim 1 wherein, upon determining that a response from the client to the first message is received by the network device within the predetermined time period, discarding a result received from the authentication server in response to the second message.

Plain English Translation

If the client authenticates using the preferred method (first message is received in time), the network device discards any result received from the authentication server that relates to the non-preferred authentication technique (second message). This ensures the device only uses the result from the chosen authentication method.

Claim 8

Original Legal Text

8. The method of claim 1 wherein the authentication server is a Remote Authentication Dial-In User Service (RADIUS) server.

Plain English Translation

In the described client authentication method, the authentication server used for the non-preferred method is a Remote Authentication Dial-In User Service (RADIUS) server. The network device sends the second message (authentication request based on MAC address, etc.) to this RADIUS server for authentication.

Claim 9

Original Legal Text

9. A device comprising: a processor; and a memory coupled with the processor and having stored therein a plurality of instructions, which when executed by the processor, cause the device to: send, to a client to be authenticated, a first message corresponding to a preferred authentication technique; send, to an authentication server, a second message corresponding to a non-preferred authentication technique such that processing by the client in response to the first message is performed in parallel to processing by the authentication server in response to the second message; determine whether a response from the client to the first message is received by the device within a predetermined time period; cause the client to be authenticated using the preferred authentication technique instead of the non-preferred authentication technique upon determining that a response from the client to the first message is received by the device within the predetermined time period; and cause the client to be authenticated using the non-preferred authentication technique instead of the preferred authentication technique upon determining that a response from the client to the first message is not received by the device within the predetermined time period.

Plain English Translation

A network device includes a processor and memory with instructions to authenticate clients using parallel authentication techniques. The device sends a first message for a preferred technique and a second message for a non-preferred technique to an authentication server. If the client responds to the first message in time, it's authenticated using the preferred technique; otherwise, the non-preferred technique is used.

Claim 10

Original Legal Text

10. The device of claim 9 wherein the preferred authentication technique is based upon IEEE 802.1x.

Plain English Translation

The network device described above uses IEEE 802.1x as the preferred authentication technique in its parallel authentication process.

Claim 11

Original Legal Text

11. The device of claim 9 wherein the non-preferred authentication technique uses a medium access control (MAC) address of the client or an Internet Protocol (IP) address of the client.

Plain English Translation

The network device, as described, uses the client's MAC address or IP address for the non-preferred authentication technique when the preferred authentication method fails or isn't supported.

Claim 12

Original Legal Text

12. The device of claim 9 wherein the first message comprises an Extensible Authentication Protocol (EAP) identifier request.

Plain English Translation

The network device sends an Extensible Authentication Protocol (EAP) identifier request as the first message, initiating the preferred authentication method in its parallel authentication approach.

Claim 13

Original Legal Text

13. The device of claim 9 wherein the second message comprises an authentication request based upon a medium access control (MAC) address of the client.

Plain English Translation

The network device sends an authentication request based on the client's MAC address as the second message to the authentication server, initiating the non-preferred authentication method.

Claim 14

Original Legal Text

14. The device of claim 9 wherein the plurality of instructions comprises instructions, which when executed by the processor, cause the device to, upon determining that a response from the client to the first message is received by the device within the predetermined time period, abort the non-preferred authentication technique-related processing performed in response to the second message.

Plain English Translation

The network device aborts the non-preferred authentication process if the client responds to the preferred authentication method (first message) within the defined timeframe.

Claim 15

Original Legal Text

15. The device of claim 9 wherein the plurality of instructions comprise instructions, which when executed by the processor, cause the device to, upon determining that a response from the client to the first message is received by the device within the predetermined time period, discard a result received from the authentication server in response to the second message.

Plain English Translation

The network device discards results from the authentication server related to the non-preferred technique if the client successfully authenticates using the preferred technique.

Claim 16

Original Legal Text

16. The device of claim 9 wherein the authentication server is a Remote Authentication Dial-In User Service (RADIUS) server.

Plain English Translation

The network device utilizes a Remote Authentication Dial-In User Service (RADIUS) server as the authentication server for the non-preferred authentication method.

Claim 17

Original Legal Text

17. A device comprising: a processor; and a memory coupled with the processor, the memory storing a plurality of instructions, which when executed by the processor, cause the device to, in response to a request received by the device from a client to access a resource: initiate a preferred authentication technique by sending a first message to the client to be authenticated; initiate a non-preferred authentication technique by sending a second message to an authentication server such that processing by the client in response to the first message is performed in parallel to processing by the authentication server in response to the second message; determine whether a response from the client to the first message is received by the device within a predetermined time period; use the preferred authentication technique instead of the non-preferred authentication technique to authenticate the client upon determining that a response from the client to the first message is received by the device within the predetermined time period; and use the non-preferred authentication technique instead of the preferred authentication technique to authenticate the client upon determining that a response from the client to the first message is not received by the device within the predetermined time period.

Plain English Translation

A device, upon receiving a resource access request from a client, initiates parallel authentication. It sends a first message for a preferred technique directly to the client and a second message for a non-preferred technique to an authentication server. The client is authenticated using the preferred technique if a timely response to the first message is received. Otherwise, the non-preferred technique is used.

Claim 18

Original Legal Text

18. The device of claim 17 wherein: the first message comprises an Extensible Authentication Protocol (EAP) identifier request; and the second message comprises an authentication request based upon a medium access control (MAC) address of the client.

Plain English Translation

In the parallel authentication process, the first message sent to the client by the network device for the preferred technique is an Extensible Authentication Protocol (EAP) identifier request. Simultaneously, the second message sent to the authentication server for the non-preferred technique is an authentication request based on the client's MAC address.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

January 23, 2012

Publication Date

August 27, 2013

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, FAQs, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “Authentication techniques” (US-8522311). https://patentable.app/patents/US-8522311

© 2026 Nomic Interactive Technology LLC. Machine-readable context available at /api/llm-context/US-8522311. See llms.txt for full attribution policy.